|
@campuscodi | |||||
|
Microsoft fixes Windows crypto bug reported by the NSA
* CVE-2020-0601 -- Windows CryptoAPI spoofing
* MSFT says bug can be used to fake file digital signatures and for MitM attacks
* NSA & MSFT say they didn't see any exploits in the wild
zdnet.com/article/micros… pic.twitter.com/IHgzsibDJa
|
||||||
|
||||||
|
Catalin Cimpanu
@campuscodi
|
14. sij |
|
The NSA security advisory, which the NSA director of cybersecurity promised in the press call, is now live, here: media.defense.gov/2020/Jan/14/20… pic.twitter.com/Q5qY3WHCg5
|
||
|
|
||
|
⛧ ʲªͷ ҎΩΰⱠᶊἕא
@Jan0fficial
|
14. sij |
|
“NSA & MSFT say they didn't see any exploits in the wild”
do they know everything? How can they possible know unless they have access to every system in the world.. if it wasn’t exploited in the wild why the urgency shown by NSA? 🤔
|
||
|
|
||
|
kevincleppe
@cleppster
|
14. sij |
|
Incredible. The NSA reported this to Microsoft? That's gotta be something that goes through VEP, right?
|
||
|
|
||
|
F1 fan on the sofa
@F1Sofa
|
15. sij |
|
It’s just means that is so bad that even they can get burned.
|
||
|
|
||
|
Muhammed Shameem
@_M_Shahnawaz
|
15. sij |
|
Did they ask their colleagues at NSA about exploitation?
|
||
|
|
||